Jaroslav Pinkava May 2001 Certification Authority in Praxis. Security Aspects. Conference Security and Protection of Information Ing. Jaroslav Pinkava,

Slides:



Advertisements
Similar presentations
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Advertisements

Public Key Infrastructure A Quick Look Inside PKI Technology Investigation Center 3/27/2002.
Practical Digital Signature Issues. Paving the way and new opportunities. Juan Carlos Cruellas – DSS-X co-chair Stefan Drees - DSS-X.
Telia Research AB György Endersz European Electronic Signature Standardisation Initiative EESSI Workshop Barcelona, György Endersz,
Telia Research AB György Endersz European Electronic Signature Standardisation Initiative EESSI Budapest Seminar at the Hungarian Communication.
ANSI/ASQ E Overview Gary L. Johnson U.S. EPA
Policy interoperability in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
An overview of legal aspects in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
1 © Cooley Godward 2001 PKI A SSESSMENT The process of evaluating, verifying, and certifying your PKI Presented by: Randy V. Sabett Vanguard Enterprise.
1 WebTrust for Certification Authorities (CAs) Overview October 2011 WebTrust for Certification Authorities (CAs) Overview October 2011 Presentation based.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
CSCE 715: Network Systems Security Chin-Tser Huang University of South Carolina.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Chapter 14 From Cryptography and Network Security Fourth Edition written by William Stallings, and Lecture slides by Lawrie Brown, the Australian Defence.
Summary of ETSI/ESI activities Andrea Caccia ETSI/ESI TB member Note: This document expresses only the views of its author.
© ETSI 2012 All rights reserved EUROPEAN UNION MANDATE/460 Kloster Banz Presented by Arno Fiedler, Member of European Telecommunications Standards.
Implementation of Electronic Signature Law Kęstutis Andrijauskas Information Society Development Committee under the Government of the Republic.
1 Bridge/Gateway CA Project Status Gzim OCAKOGLU European Commission – DG ENTR / IDABC Reykjavik – 27 May 2005.
21 mai 2015 Bridges between Certification Authorities.
HIT Standards Committee: Digital Certificate Trust – Policy Question for HIT Policy Committee March 29, 2011.
PAPERLESS BUSINESS in GEORGIAN FINANCIAL SECTOR NANA ENUKIDZE - Advisor to the Governor.
EESSI European Electronic Signature Standardisation Initiative
Legal Issues on PKI & qualified electronic certificates. THIBAULT VERBIEST Attorney-at-law at the Brussels and Paris Bar Professor at the Universities.
Information security An introduction to Technology and law with focus on e-signature, encryption and third party service Yue Liu Feb.2008.
1 Evaluating Systems CSSE 490 Computer Security Mark Ardis, Rose-Hulman Institute May 6, 2004.
EESSI Overview - 1August 2002 EESSI European Electronic Signature Standardisation Initiative Implementing Electronic Signature.
DIGITAL SIGNATURE AND ELECTRONIC DOCUMENTS IN ITALY Prof. Pierluigi Ridolfi AIPA Authority for Information Technology in the Public Administration V. Solferino,
The Icelandic PKI project Jóhann Gunnarsson Head of Division, Ministry of Finance.
Resource PKI: Certificate Policy & Certification Practice Statement Dr. Stephen Kent Chief Scientist - Information Security.
European Electronic Signature Standardization
European Signatures versus Global SignaturesRome, 7 April, 2003 EESSI open specifications and interoperability The state of the art in Italy Giovanni Manca.
István Rényi Communication Authority, Hungary Panel 2: „ Development and market uptake of standards of the EESSI programme” Republic.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
PKI Services for the Public Sector of the EU Member States Dr. Dimitrios Lekkas Dept. of Products & Systems Design Engineering University of the Aegean.
European Union Agency for Network and Information Security Follow ENISA: ENISA and standards Sławomir Górniak European Union Agency.
OASIS OASIS Digital Signature Services Juan Carlos Cruellas Juan Carlos Cruellas Andreas Kuehne Stefan Drees Ernst Jan van Nigtevecht.
8 Nob 06 / CEN/ISSS ETSI STF 305: Procedures for Handling Advanced Electronic Signatures on Digital Accounting CEN/ISSS Workshop.
Circulation of authentic instruments under Regulation 650/2012 speaker – Ivaylo Ivanov – Bulgarian Notary Chamber.
E-Signatures The Community framework on e-signatures (Directive 1999/93/EC) Dr Ioannis Iglezakis Visiting Lecturer University of Thessaloniki, Greece.
EGov Interop'05 - Feb 23-24, Geneva (Switzerland) OBSERVATORY ON INTEROPERABLE eGOVERNMENT SERVICES eGov-Interop'05 Annual Conference February.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
WebTrust SM/TM Principles and Criteria for Certification Authorities CA Trust Jeff
Transboundary Trust Space September 19, 2012 Development trends of legal acts in forming valid transboundary electronic interaction Alexander Sazonov Regional.
HEPKI-TAG UPDATE Jim Jokl University of Virginia
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
CEN WS/BII The BII post-award activities and deliverables The path towards more efficient procurement in Europe Stockholm December 2, Mr. Martin.
FOURTH EUROPEAN QUALITY ASSURANCE FORUM "CREATIVITY AND DIVERSITY: CHALLENGES FOR QUALITY ASSURANCE BEYOND 2010", COPENHAGEN, NOVEMBER IV FORUM-
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Electronic Signature infrastructure for Europe Riccardo Genghini Cen/Isss.
A Brief Overview of draft-ietf-sidr-cp-01.txt draft-ietf-sidr-cps-rirs-01.txt draft-ietf-sidr-cps-isp-00.txt Steve Kent BBN Technologies.
Higher Education PKI Summit Meeting August 8, 2001 The ABA PAG Rodney J. Petersen, J.D. Director, Policy and Planning Office of Information Technology.
UNECE – SIDA “ SOUTH EAST EUROPE REGULATORY PROJECT” FIRST MEETING OF REGULATORS FROM SOUTH EAST EUROPEAN COUNTRIES PRESENTATIONFROM THE REPUBLIC OF MACEDONIA.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
EESSI June 2000Slide 1 European Electronic Signature Standardization Hans Nilsson, iD2 Technologies, Sweden.
Evolving Issues in Electronic Data Collection Workshop Interoperability Russ Savage Electronic Transactions Liaison Arizona Secretary of State Office.
Approximation of legislation to the internal market acquis An EU funded project managed by European Agency for Reconstruction Directive 89/106/EEC on Construction.
Cryptography and Network Security Chapter 14 Fourth Edition by William Stallings Lecture slides by Lawrie Brown.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
PKI Future Directions 29 November 2001 Russ Housley RSA Laboratories CS – Class of 1981.
IDI Conference The digital signature of InfoCamere a practical and effective means for business Turin, 6 th of June Gabriele DA RIN.
Agreement concerning the adoption of uniform conditions for periodical technical inspections of wheeled vehicles and the reciprocal recognition of such.
Federal Department of Environment, Transport Energy and Communications UVEK Federal Office of Communications OFCOM Telecom/FG, Fix Network and Universal.
ETSI TC ESI PRESENTATION TO CAB FORUM Iñigo Barreira /Arno FiedlerFebruary 2016 meeting, Scottsdale, AZ © ETSI All rights reserved.
Information day on EUROCONTROL Guidance Material on the application of Common Requirements for Service Provision TECHNICAL & OPERATIONAL COMPETENCE ATS.
Implementation of the Digital Tachograph Card Issuing System in Poland – Case Study Speaker: Piotr KUŹNIAK – Polish Security Printing Works
OASIS Juan Carlos Cruellas – UPC Stefan Drees - DSS-X co-chair Nick Pope – Thales eSecurity OASIS Digital Signature Services and ETSI standards Juan Carlos.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
Keith Dickerson Chairman, ICTSB
Draft ETSI TS Annex C Presented by Michał Tabor for PSD2 Workshop
PKI Services for the Public Sector of the EU Member States
جايگاه گواهی ديجيتالی در ايران
Presentation transcript:

Jaroslav Pinkava May 2001 Certification Authority in Praxis. Security Aspects. Conference Security and Protection of Information Ing. Jaroslav Pinkava, CSc. AEC spol. s r.o.  Norman Czech Republic

Jaroslav Pinkava May 2001 Introduction some overview of the most important security character problems tied with functionality of certification authority cryptographic side CP + CPS EU standards in preparation. EESSI: ETSI + CEN/ISSS

Jaroslav Pinkava May 2001 Certification Policy set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements The assessed set of certificate policies is then indicated by the issuing CA in the CA-certificate.

Jaroslav Pinkava May 2001 Certification Policy The following extension fields in an X.509 certificate are used to support certificate policies: Certificate Policies extension; Policy Mappings extension; Policy Constraints extension.

Jaroslav Pinkava May 2001 Certification Practice Statement A statement of the practices which a certification authority employs in issuing certificates. form of a declaration by the certification authority of the details of its trustworthy system and the practices it employs in its operations and in support of issuance of a certificate, or it may be a statute or regulation applicable to the certification authority and covering similar subject matter.

Jaroslav Pinkava May 2001 Certification Practice Statement CPS should indicate any of the widely recognized standards to which the certification authority's practices conform. generally be more detailed than certificate policy definitions.

Jaroslav Pinkava May 2001 CPS versus CP detailed CPS does not form a suitable basis for interoperability between CAs operated by different organizations. Rather, certificate policies best serve as the vehicle on which to base common interoperability standards and common assurance criteria on an industry-wide (or possibly more global) basis.

Jaroslav Pinkava May 2001 Security problems connected with CA functioning Physical Security Controls Procedural Controls Personnel Security Controls

Jaroslav Pinkava May 2001 Technical security controls Key Pair Generation and Installation; Private Key Protection; Other Aspects of Key Pair Management; Activation Data; Computer Security Controls; Life-Cycle Security Controls; Network Security Controls; and Cryptographic Module Engineering Controls.

Jaroslav Pinkava May 2001 Forthocoming EU Standards Final report EESSI European Directive on Electronic Signatures, December 1999 “Member States shall bring into force the laws, regulations and administrative provisions necessary to comply with this Directive before 19 July 2001”.

Jaroslav Pinkava May 2001 EESSI SG EESSI: European Electronic Signature Standardization Initiative European Telecommunications Standards Institute

Jaroslav Pinkava May 2001 EESSI Standards Overview Signature creation process and environment Signature validation process and environment Signature format and syntax Creation device Qualified Certificate policy Trustworthy system Certification Service Provider Subscriber/signer Relying party CEN E-SIGN ETSI ESI Qualified certificate

Jaroslav Pinkava May 2001 EESSI The last slide is from presentation: György Endersz, Telia Research AB, Sweden Chairman ETSI ESI Working Group on workshop of European Electronic Signature Standardisation Initiative - Barcelona September 2000

Jaroslav Pinkava May 2001 References ETSI: Sign up from Web-site to open El Sign mailing list CEN: EESSI: homepage.htm ISSE Conference & Workshops:

Jaroslav Pinkava May 2001 ETSI - Policy Requirements for CSPs Issuing Qualified Certificates; - Qualified Certificates Profile; - Time Stamping Profile; - Electronic Signature Formats. (finalized)

Jaroslav Pinkava May 2001 ETSI Security management and policy requirements for CSPs issuing time stamps - Policy requirements for CAs issuing other than Qualified Certificates - Policies for CSP's - Electronic Signature syntax and encoding formats in XML - Technical aspects of signature policies (Informative annex to TS ) - Infrastructure and interoperability requirements for provision of status information on Certification Service Providers

Jaroslav Pinkava May 2001 CEN/ISSS Area D Security Requirements for Trustworthy Systems Managing Certificates for Electronic Signatures New area D2 security requirements for cryptographic modules used in trustworthy systems run by CSPs issuing qualified certificates

Jaroslav Pinkava May 2001 CEN/ISSS Area F Secure Signatur-Creation Devices, version 'EAL 4', version 'EAL 4+', two approved versions

Jaroslav Pinkava May 2001 CEN/ISSS Area G1 Security Requirements for Signature Creation Systems (approved)

Jaroslav Pinkava May 2001 CEN/ISSS Area G2 Procedures for Electronic Signature Verification (approved)

Jaroslav Pinkava May 2001 CEN/ISSS Area V EESSI Conformity Assessment Guidance Part 1: General (approved) Part 2: Certification Authority services and processes (approved) Part 3:Trustworthy systems managing certificates for electronic signatures Part 4:Signature creation applications and procedures for electronic signature verification Part 5: Secure signature creation devices

Jaroslav Pinkava May 2001 CEN/ISSS -New areas in 2001 Area AA Extension of SSCD requirements towards specific applications/environments and towards e-commerce applications - Art5.2 Area K Requirements for smart cards used as SSCD

Jaroslav Pinkava May 2001 Thanks for Your Attention.